git-fastclone before 1.0.1 permits arbitrary shell command execution from .gitmodules. If an attacker can instruct a user to run a recursive clone from a repository they control, they can get a client to run an arbitrary shell command. Alternately, if an attacker can MITM an unencrypted git clone, they could exploit this. The ext command will be run if the repository is recursively cloned or if submodules are updated. This attack works when cloning both local and remote repositories.
oryginał ENCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HSquareup Git Fastclone
APPSquareup< 1.0.1
Powiązane podatności
Command injection w Squareup git-fastclone — wykonanie dowolnych poleceń
XXE w Squareup Retrofit umożliwiające odczyt plików i SSRF
Wire (gRPC/protobuf): brak walidacji długości pola powoduje crash usługi
Square Retrofit version versions from (including) 2.0 and 2.5.0 (excluding) contains a Directory Traversal vul...
A flaw was found in Red Hat's AMQ-Streams, which ships a version of the OKHttp component with an information d...